By looking the list of negative sides of DNS over TLS (DoT) in there, this project seems to list artificial problems, which makes me want to avoid the whole project. Maybe there are real benefits on using this protocol, but they should not make the list of problems looking longer than it actually is.
The project especially lists the problems of TLS. TLS is one of the most understood, tested, and well-defined protocols that can be abstracted away in implementation level. Nothing also prevents forcing TLS 1.3 which removes most of the described other problems.
This especially sounds odd:
> Questionable practical benefits over DoH
But DoH brings the full TLS stack and also the HTTP stack as well? At the same time the project complains about increased attack surface in DoT, but DoH just extends it even more.
If I also look the DoH list, there is
> Requires TCP
But just few lines befeore, they say that DoH supports HTTP/3 which is UDP.
E.g. Android has supported it 3 years already:
https://security.googleblog.com/2022/07/dns-over-http3-in-an...